Active Directory Remediation via Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and visualizing complex active directory structures is challenging due to difficulties in accurately editing, controlling, and remedying group hierarchies, access permissions, and identifying unused or low-confidence groups, which leads to security breaches and resource inefficiencies.

Innovation Solution

The solution involves an apparatus and method for active directory management and remediation that determines direct and indirect access based on group hierarchies, identifies owners, and performs automated remediation actions such as removing unnecessary access and unused groups, using data models, graph generators, and visualization tools to provide insights and clean up active directory structures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual management of active directory group hierarchies is used, then flexibility in access control is maintained, but management complexity and time consumption increase significantly

Engineering Contradiction:
Improveactive directory managementVSAvoidtime for editing and controlling group hierarchies
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs automated remediation actions including self-identification of unused groups, self-detection of incorrect access grants, and self-execution of remediation tasks such as removing unnecessary access permissions and cleaning up group hierarchies without requiring manual intervention for each task

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical operations of managing active directory structures with an automated computational system that uses graph analysis algorithms to identify relationships, calculate confidence scores, and execute remediation actions automatically

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive access control monitoring is implemented, then security is improved, but system complexity and resource utilization increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex active directory structure into discrete graph entities (users, groups, resources) with defined relationships, allowing individual analysis of each component and its access permissions without requiring analysis of the entire system at once

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary graph analysis layer that sits between the active directory system and the monitoring functions, translating complex directory structures into analyzable graph representations with confidence scores that simplify security analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If automated remediation actions are performed, then security breaches are prevented, but risk of incorrect access removal increases

Engineering Contradiction:
Improvesecurity breach preventionVSAvoidaccuracy of access permission management
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The system calculates confidence scores based on multiple factors including group hierarchy depth, membership counts, and access patterns, providing feedback that indicates the likelihood of correct versus incorrect access grants, allowing prioritized remediation of high-confidence issues

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary analysis and identification of potential security issues before executing remediation actions, generating a ranked list of remediation targets based on confidence scores that allows review and approval before automatic correction

Inventive Principle:
Principle #10Preliminary action

4Loss of information

If detailed visualization of group hierarchies is provided, then management insights are improved, but data processing requirements and resource usage increase

Engineering Contradiction:
Improvemanagement insightsVSAvoiddata processing resources
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The system provides detailed visualization and analysis focused on specific local areas of the active directory structure that require attention, such as groups with low confidence scores or unusual access patterns, rather than uniformly processing and displaying information about all groups and users

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4125014A1Active directory management and remediation
Publication Date: 2023.02.01 ACCENTURE GLOBAL SOLUTIONS LTD
  • EP4125014A1 patent drawingFigure 1
  • EP4125014A1 patent drawingFigure 2A
  • EP4125014A1 patent drawingFigure 2

AI summary

In some examples, active directory management and remediation may include obtaining data associated with active directories, and generating, based on the obtained data, a data model that includes a plurality of active directory concepts. A graph may be generated and include the active directory concepts as nodes and relationships between the nodes. The graph may be analyzed to identify user to group memberships. A membership score and a reasoning for the membership score may be determined for each identified user to group membership of the user to group memberships. The membership score and the reasoning for the membership score may be analyzed for each identified user to group membership. Further, based on the analysis of the membership score and the reasoning for the membership score, the at least one of the user to group memberships may be remediated.